WorkThe story, in brief

China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade - The Hacker News

A decade-long backdoor in Linux login software just exposed. Here's why your AI infrastructure is vulnerable.

Paper-cut illustration of a coral software window opening into a three-dimensional drafting space.
New tools for building and creating with AI.AI illustration by KeyNews
The KeyNews take

Why it matters

Supply chain security in critical infrastructure is directly relevant to AI companies building on Linux systems and cloud platforms. A nearly 10-year undetected compromise of foundational software raises urgent questions about software bill-of-materials (SBOM) audit practices that AI labs depend on for secure model deployment and data center operations.

The key facts

10 to know
  1. China-linked hackers backdoored Linux login software (xz Utils)

  2. Compromise remained undetected for nearly a decade

  3. Affects foundational infrastructure used across AI data centers and cloud platforms

  4. Highlights supply chain vulnerability in open-source software critical to AI ops

  5. Published June 12, 2026

  6. China-linked threat actor identified

  7. Backdoor embedded in Linux login software

  8. Nearly decade-long undetected presence (approximately 10 years)

  9. Supply chain attack on widely-used authentication layer

  10. Affects Linux systems across enterprises and AI infrastructure providers

Go to the source

Reuters Technologynews.google.com

Publisher excerpt: China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade The Hacker News
Read original report
Back to today's editionMore work news

The wider picture

View all
Illustration of independent geometric mechanisms passing paper tasks along branching amber tracks.
AI illustration by KeyNews
Work01

The Emerging M&A Map For AI Agent Security

As agents move from pilots to production with real system access, enterprise security models are breaking. The M&A map is forming around who controls agent permissions, monitoring, and governance — a new class of identity management problem that practitioners need to architect for now.

Crunchbase News
Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
AI illustration by KeyNews
Work02

AI privacy budgets: Ask for the calculation, not the claim

Enterprise AI buyers are accepting privacy budget numbers without verification. This deep dive explains what questions to ask vendors about federated learning privacy claims, and why the gap between contractual promises and operational evidence is where real exposure lives.

CIO
Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
AI illustration by KeyNews
Work03

Andrew Kelley Interview: Why He Built Zig, Banned AI Contributions, and Moved Zig off GitHub

Open-source governance is shifting in response to AI-generated contributions. Zig's formal ban and migration off GitHub signals broader industry concern about code quality, maintainer burden, and the cultural impact of automated submissions — a flashpoint for how AI changes the work of software development.

InfoQ AI/ML